02-18-20 - Let's Blow Our Entire Marketing Budget at RSA

Let's Blow Our Entire Marketing Budget at RSA

CISO | Security Vendor Relationship Series

This week's episode of CISO/Security Vendor Relationship Podcast

Let's Blow Our Entire Marketing Budget at RSA

 features my co-host Mike Johnson and sponsored guest Tom Garrison, vp and gm of client security strategy at Intel . The three of us discussed:

Have a before, during, and after plan for RSA.

The mega security conference is overwhelming. I know you want to make a big splash at the event. Problem is everyone else wants to make a big splash. There's just so much attention available. Those who make the biggest splash have the most unique news, or win the awards. For everyone else, take value in the relationships you build. If you're sending a whole team to RSA, have a post show debrief where everyone is required to educate the rest of the team on what they learned and who they met at the event.

David Spark, CISO Series, Tom Garrison, Intel, and Mike Johnson,

CISO/Security Vendor Relationship Podcast

Innovation doesn't stop when the product launches.

Even though a product is sold in a moment in time, it needs to evolve, mostly to stay ahead of the attacks. 

Validate your technology supply chain.

Given that Intel has relationships with so many manufacturers, they're in a great position to start the Compute Lifecycle Assurance (CLA) initiative. As technology makes its way into your pipeline, it's an opportunity to verify the integrity of materials and security settings of materials. And ultimately, how do you retire that technology, not just destroying the data, but also the components, in a safe and potentially reusable manner.

Use the questioning tactic of "Five Whys" for incident response.

This design philosophy asks a series of successive 'whys' to determine the root cause of why we choose certain behaviors. Once you know the core reason, you'll be able to understand the intended reason for a given attack, leading to a better incident response.

Thanks to this week's podcast sponsor, Intel

Intel's Compute Lifecycle Assurance

The globalization of technology has created an environment of complicated supply chains with limited transparency. Intel’s Compute Lifecycle Assurance (CLA) initiative solves this through a range and tools and solutions that deliver assurances of integrity throughout the entire lifetime of a platform --from build to retire.

Don't miss our LIVE SHOWS in SF, NYC, and Boston

We've got three live audience recordings coming up in just two weeks. Please come on out to see and participate if you're going to be in San Francisco for RSA, or you'll be in New York City or Boston the following week.Sunday, 2/23/20 in San Francisco at BsidesSF - 3:30 PMMike Johnson and I welcome Olivia Rose, CISO, Mailchimp for a recording in a movie theater during BsidesSF. You must purchase a ticket to BsidesSF and then register for our session.Tuesday, 3/3/20 in New York City at Rise-NYC - 5:30 PMJoining me will be guest co-host JJ Agha, vp, head of InfoSec, WeWork along with a special guest. This will be done in conjunction with NY Information Security Meetup Group that has over 5,000+ members. Small fee to attend since space is limited. REGISTER.Thursday, 3/5/20 in Boston at athenahealth - 6:00 PMMy special guest cohost will be Taylor Lehmann, CISO, athenahealth, and our guest will be Marnie Wilking, global head of security & technology risk management at Wayfair. REGISTER.

Allan Alford on why CISOs are fired after breaches

SUBSCRIBE TO BOTH PODCASTS

Go ahead and click on any of these links to subscribe to the podcast feed of your favorite podcast catcher.

If you're already a subscriber, THANK YOU! If you like either or both shows, please tell all your friends on social media and write a review on iTunes.